-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathwebauthn-assert-options.php
More file actions
53 lines (45 loc) · 1.58 KB
/
Copy pathwebauthn-assert-options.php
File metadata and controls
53 lines (45 loc) · 1.58 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
<?php
/**
* WebAuthn assertion — get options for biometric login (by username)
*/
require_once __DIR__ . '/auth.php';
header('Content-Type: application/json; charset=utf-8');
setSecurityHeaders();
$username = isset($_GET['username']) ? trim((string) $_GET['username']) : '';
$safeUser = preg_replace('/[^a-zA-Z0-9_]/', '', $username);
if ($safeUser === '') {
echo json_encode(['success' => false, 'error' => 'Username required']);
exit;
}
session_start();
$challenge = random_bytes(32);
$_SESSION['webauthn_assert_challenge'] = base64_encode($challenge);
$_SESSION['webauthn_assert_user'] = $safeUser;
$credFile = __DIR__ . '/data/' . $safeUser . '/webauthn_credentials.json';
$allowCredentials = [];
if (is_file($credFile)) {
$raw = file_get_contents($credFile);
$creds = $raw ? json_decode($raw, true) : [];
if (is_array($creds)) {
foreach ($creds as $c) {
if (!empty($c['id'])) {
$allowCredentials[] = [
'type' => 'public-key',
'id' => $c['id']
];
}
}
}
}
if (empty($allowCredentials)) {
echo json_encode(['success' => false, 'error' => 'No biometric credential for this user']);
exit;
}
$options = [
'challenge' => rtrim(strtr(base64_encode($challenge), '+/', '-_'), '='),
'timeout' => 60000,
'rpId' => isset($_SERVER['HTTP_HOST']) ? preg_replace('/^www\./', '', $_SERVER['HTTP_HOST']) : 'localhost',
'allowCredentials' => $allowCredentials,
'userVerification' => 'preferred'
];
echo json_encode(['success' => true, 'options' => $options]);